CVE-2021-22680

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
03/05/2022
Last modified:
11/05/2022

Description

NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nxp:mqx:*:*:*:*:*:*:*:* 5.1 (including)


References to Advisories, Solutions, and Tools